Mizuho Corporation (hereinafter referred to as “Mizuho” or “we”/”our”/”us”) recognizes that protection of personal data of our customers (hereinafter referred to as “you”/”your”) is an important corporate responsibility of Mizuho. Protecting personal data is also a practice that wins the trust of the international community including Japan, which is essential when engaging in business on a global basis.
Mizuho has adopted a privacy policy based on GDPR and CCPA (hereinafter referred to as this “Privacy Policy”) on our collection and use (when used collectively, hereinafter referred to as “processing”) of your Personal Data (which means the “personal information” and “personal data” as defined in the Japanese Act on the Protection of Personal Information, “personal data” defined in the EU General Data Protection Regulation (“GDPR”), and California Consumer Privacy Act of 2018 (“CCPA”), collectively). We have also established a compliance framework, and will ensure that our officers and employees are fully aware of this Privacy Policy.
In the course of providing goods or services to customers, Mizuho collects such Personal Data from you (including from your officers or employees) as your name, address, and contact information. In the course of collecting Personal Data from you, we will clearly indicate the purpose of collection and the scope of usage of the Personal Data, and collect Personal Data only to the extent necessary. Your submission of Personal Data to us is not a requirement of or condition to the execution of any contract between you and Mizuho, and you are under no obligation to provide Personal Data to us. You will not be adversely affected if you fail to provide us with your Personal Data.
In the course of transactions involving our products and services, Mizuho may collect Personal Data through the following means:
Mizuho may collect the following Personal Data.
If CCPA applies, Personal Data collected, disclosed or shared during the last 12-month period for business purposes are, from the categories set forth in Items (1) through (6) above as follows:
With regard to the above categories of Personal Data, party from which Personal Data is collected, commercial purpose of collection, and scope within which Personal Data is provided or shared are as follows:
Category of Personal Data | Collected from | Purpose of collection | Provided to |
---|---|---|---|
Name | business partner | Sales promotion of products handled by Mizuho | Mizuho's affiliate |
email address | same as above | same as above | same as above |
telephone number | same as above | same as above | same as above |
If CCPA applies, and Personal Data classified under a category other than those enumerated in this Privacy Policy is to be used, or Personal Data classified under a category enumerated in this Privacy Policy is to be used for purposes other than those set forth herein, Mizuho will first take the steps, if any, required under this Privacy Policy, and use Personal Data after changing or updating this Privacy Policy to comply with such use.
The provisions of this Article 3 apply only to processing of Personal Data for those residing in the European Economic Area (EEA) member countries.
As a general rule, the legal basis for the processing of Personal Data by Mizuho is your consent.
The legal bases for the processing of Personal Data when you have not given us your consent are when processing is needed (i) for Mizuho to perform our contract with the customer; complete procedures at your request prior to execution of a contract; comply with our legal obligations; protect your interests and interests of other persons concerning their life and body; perform our duties for the public interest, and (ii) for the protection of legitimate interests of Mizuho or other third parties. Legitimate interests of Mizuho or other third parties include improvements of our products and services, and improvements to the usability and security features of our website.
You may withdraw their consent on the processing of Personal Data at any time. Your withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. You have the right to withdraw your consent by contacting Mizuho Personal Information Center.
Mizuho will use your Personal Data only within the scope and for the purposes set forth below in Paragraph 4-2, and for no other purposes.
Mizuho will use your Personal Data for the following purposes:
In addition to providing information directly to customers, Mizuho may also provide information in the form of direct mail and email marketing.
If Personal Data is to be processed for any purpose other than those listed above, Mizuho will notify you clearly setting forth the purpose and scope of the processing, and obtain their consent before such data is collected or used.
You may decide that you do not wish to have all or part of their Personal Data collected and owned by Mizuho used for the purpose of direct mail and email marketing. In such case, please contact Mizuho Personal Information Center at the contact address set forth in Article 9 below. We will do our best to meet your wishes.
If we are to provide third parties with data identical to all or part of your Personal Data that we are keeping, we will make the transfer only after obtaining your consent, unless the provision falls under any of the exemptions under GDPR, CCPA or the laws of Japan. In such case, we will select third parties with care, and request that they take the same appropriate measures in the management of Personal Data in accordance with GDPR, etc., as taken by Mizuho.
When using your Personal Data, Mizuho may entrust the handling, etc. of the Personal Data to third party service providers within the scope of the purposes of use. We will impose an obligation upon the service providers to strictly manage Personal Data at the same level as they are managed by Mizuho, and we will monitor the service providers in a suitable manner. When entrusting handling, etc. of Personal Data of customers residing in EEA member countries to service providers, we will comply with the security management of Personal Data by executing a contract including standard contractual clauses prescribed by GDPR.
Within the scope of the purpose of use set forth in Article 4-2, Mizuho may jointly use your Personal Data with Mizuho Group companies (Mizuho Medical Co., Ltd. http://www.mizuhomedical.co.jp/、Mizuho Urban Co., Ltd. ) and other business operators that we will clearly indicate. Personal Data that will be jointly used is as follows. The business operator that first collected such Personal Data is responsible for the management of such data.
Mizuho will take appropriate measures to ensure that your Personal Data is kept accurate and up-to-date.
Mizuho will retain Personal Data for as long as it is necessary to fulfill the purposes of their use. Upon expiry of this retention period, we will erase, pseudonymize or anonymize the Personal Data in a manner ensuring their safety within a reasonable period. In the retention, erasure, pseudonymization, or anonymization of Personal Date, we will comply with laws, regulations, and other requirements of the territories in which Mizuho operates.
Mizuho will not make decisions based solely on automated processing, including profiling of Personal Data.
You have the following rights under GDPR, etc. (excluding CCPA; the same applies hereafter in this Article 6). You are able to exercise these rights by contacting (either by email or telephone) Mizuho Personal Information Center. When you notify us that you wish to exercise your rights, and after we verify your identification, we will, as a general rule, contact you within one (1) month from the date of receipt of your notice, unless the matter falls under any of the exceptions provided in GDPR, etc.
If CCPA applies, individuals (including any of your employees to whom CCPA applies; the same applies hereinafter) who are “consumers” under CCPA have the following rights. “Consumers” are able to exercise these rights by contacting (either by email or telephone) Mizuho Personal Information Center set forth in 9. below.
If a “consumer” under CCPA requests disclosure of his/her Personal Data pursuant to (1) or (2) above, Mizuho will respond to such request within the period required under CCPA after verification that the request is being made by the customer himself/herself in a manner set forth below. In any of the following cases, Mizuho may request submission of information that is only possessed by the “consumer” himself/herself.
If, on the other hand, a “consumer” under CCPA requests deletion of his/her Personal Data pursuant to the above, Mizuho respond to the request within the period required by CCPA upon verifying the request by a method that Mizuho considers appropriate according to the category of Personal Data being deleted. In such case, Mizuho may request the “consumer” to provide information that only the “consumer” possesses.
You have the right to lodge a complaint with a supervisory authority of a country, territory, international organization, etc. in accordance with GDPR, etc. regarding Mizuho's handling of their Personal Data.
A consumer under CCPA may exercise the right set forth in 6-5 through an authorized agent. In such case, such consumer shall submit to Mizuho a power of attorney signed by itself. In addition, Mizuho will ask the authorized agent for identification verification in the same manner as set forth in 6-5.
Mizuho expects to transfer Personal Data collected from EEA member countries to Japan or other countries, territories or international organizations, etc. within/outside EEA. Countries to which we intend to transfer Personal Data include countries recognized in GDPR as providing adequate level of data protection (which includes Japan as well as Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, and Uruguay) but also countries for which an adequacy decision has not been adopted. Mizuho will not transfer your Personal Data to a country without an adequacy decision unless we receive your explicit consent to the transfer, or the receiver has either signed a contract to comply with binding corporate rules (“BCR”) based on GDPR, or we have entered into contract with the receiver containing standard contractual clauses (“SCC”) which are found to offer adequate protection under GDPR. If you submitted the relevant Personal Data, we will disclose a copy of these contracts if any has been executed, after masking any confidential information, if you request for such disclosure.
Mizuho complies with the GDPR, CCPA as well as other relevant laws, regulations, and industry guidelines.
Mizuho makes every effort to protect customers' Personal Data, including taking with preventive and security measures to protect against unauthorized access, destruction, tampering, or divulgence.
Mizuho has an organizational system in place for the protection of Personal Information, including a Data Protection Officer (“DPO”) to oversee compliance, and personal information management officers in each department.
Mizuho has established rules on the handling of Personal Data setting standards on appropriate acquisition, maintenance, use, and disposal of Personal Data, and ensuring that these standards are strictly complied. We also adopted a code of conduct and concrete rules for the prevention of unauthorized access, destruction, tampering and divulgence of Personal Data.
Mizuho has in-house training programs on protection of Personal Data. We are committed to protecting Personal Data by ensuring that our employees are made fully aware of the details of personal data protection.
Mizuho reviews and improves the rules on the handling of Personal Data and the organizational system for implementing those rules on an on-going basis, to ensure that their implementation continues to be effective and appropriate.
Mizuho has established a customer service desk to respond to your inquiries, comments, and complaints regarding your Personal Data collected and kept by Mizuho. After conducting the required verification of your identification or the identification of your agent, we will provide a response that we determine in good faith to be reasonably necessary. Please note that depending on the inquiry, comment, or complaint, it may take some time for us to provide a response.
Mizuho will update this Privacy Policy as it deems necessary. If CCPA applies, this Privacy Policy will be updated at least once every 12 months.